Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

May 24, 2007 12:00 AM

Logging Remote Desktop Connections

Windows IT Pro
InstantDoc ID #95602
Rating: (0)

Q: We believe someone at our company is using another employee's account to access a workstation remotely via Remote Desktop Connection. We know the authorized employee couldn't have accessed the workstation because at that time he was on a 12-hour flight with no Internet access. Can we get a list of all the Remote Desktop logons to our workstations from Small Business Server’s (SBS's) Security log?

A: The short answer is no. Your question illustrates why it’s so important to enable auditing not only on your domain controllers (DCs), but also on your workstations and member servers.

Assuming the SBS system is your only server, it’s also your DC. And if the SBS system's audit policy is configured with default settings, the Security log will have a record of all the successful authentications of domain accounts—including Remote Desktop logons to workstations. (Default audit policy enables only successful account logon events—not failures.) In your DC's Security log, look for event ID 672 (authentication ticket granted) in which the service name is the computer name of the workstation that was accessed. Also look for event ID 680 (account used for logon by) where the workstation name matches that of the accessed workstation. In both events, the description’s User Name line will identify the user who was authenticated to the workstation.

However, you must understand that DCs log authentication events—not logon events (there's a difference). Authentication is the same to a DC no matter what type of logon occurs at the workstation. From the DC’s Security log you can't determine whether the authentication event was caused by a Remote Desktop Connection logon, a local console logon, or a logon to a shared folder on the workstation. The only way to find out what caused the authentication event is to enable the workstation's logon/logoff auditing. Most Windows workstations don’t enable auditing by default, so unless you’ve already enabled logon auditing for the workstation, no such record exists. Also note that DC Security logs show only authentication events involving domain accounts. Any attempt to log on to a workstation using a local account in the workstation’s SAM will show up only in that workstation's Security log, not in the DC's Security log.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.